You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Dependabot has flagged 7 open security vulnerabilities (2 critical, 5 medium). All affected dependencies are in upstream SGLang code (sgl-model-gateway/ and docs/), not Engram fork additions.
Critical:google.golang.org/grpc auth bypass (CVE-2026-33186) in 2 Go modules Medium: 3 wasmtime CVEs + jsonwebtoken type confusion in Cargo.toml, urllib3 redirect bypass in docs/requirements.txt
Summary
Dependabot has flagged 7 open security vulnerabilities (2 critical, 5 medium). All affected dependencies are in upstream SGLang code (
sgl-model-gateway/anddocs/), not Engram fork additions.Critical:
google.golang.org/grpcauth bypass (CVE-2026-33186) in 2 Go modulesMedium: 3
wasmtimeCVEs +jsonwebtokentype confusion in Cargo.toml,urllib3redirect bypass in docs/requirements.txtFull alert details: https://github.com/Clarit-AI/Engram/security/dependabot
Action Plan
Detailed remediation instructions and agent context tracked in Linear KHA-252.